]> git.proxmox.com Git - mirror_edk2.git/commit - OvmfPkg/OvmfPkgIa32X64.dsc
OvmfPkg: exclude libssl functionality from OpensslLib if TLS_ENABLE=FALSE
authorLaszlo Ersek <lersek@redhat.com>
Thu, 23 Feb 2017 20:46:06 +0000 (21:46 +0100)
committerLaszlo Ersek <lersek@redhat.com>
Sat, 25 Feb 2017 13:56:53 +0000 (14:56 +0100)
commitdf453e1b7c7c3612d1fa3311bfb4c9d153ec9ad8
treef13f9a63872d8165cc47c858d01540c72bc0596f
parent622627f80f2584c3d1dbe49ce363002381923510
OvmfPkg: exclude libssl functionality from OpensslLib if TLS_ENABLE=FALSE

The OpensslLibCrypto library instance (which does not contain libssl
functions) is sufficient for the Secure Boot feature.

Ease security analysis by excluding libssl functionality from the
OpensslLib instance we use with TLS_ENABLE=FALSE.

Cc: Gary Lin <glin@suse.com>
Cc: Jordan Justen <jordan.l.justen@intel.com>
Cc: Tomas Hoger <thoger@redhat.com>
Contributed-under: TianoCore Contribution Agreement 1.0
Signed-off-by: Laszlo Ersek <lersek@redhat.com>
Reviewed-by: Gary Lin <glin@suse.com>
OvmfPkg/OvmfPkgIa32.dsc
OvmfPkg/OvmfPkgIa32X64.dsc
OvmfPkg/OvmfPkgX64.dsc